1. Overview
Emore (“we”, “our”, or “us”) is an online retail platform operated by SoftlaneIT (Pvt) Ltd, registered in Sri Lanka. We are the data controller for personal information collected through emo.lk and our mobile applications.
This Privacy Policy describes how we collect, use, disclose, and safeguard your personal data. It applies to all visitors, customers, and registered users. By using our services you agree to the practices described here.
2. Data We Collect
2.1 Data You Provide Directly
- Account registration: first name, last name, email address, password (hashed).
- Orders & checkout: shipping address, billing address, phone number, order notes.
- Warranty claims: product issue descriptions, photos, purchase evidence.
- Reviews & Q&A: ratings, written reviews, product questions.
- Contact form: name, email, message content.
- Google sign-in (optional): Google profile ID, name, email.
2.2 Data Collected Automatically
- Usage data: pages visited, click events, session duration, referring URLs.
- Device data: IP address, browser type and version, operating system, screen resolution.
- Cookies & local storage: session tokens, preference data, consent records — see Section 8.
- Transaction metadata: PayHere payment reference IDs (we do not store full card numbers).
2.3 Data From Third Parties
- Google OAuth: if you sign in with Google, we receive your public profile data from Google LLC.
- Payment gateways: PayHere provides transaction status and reference numbers.
3. How We Use Your Data
| Purpose | Data Used |
|---|---|
| Process and fulfil orders | Name, address, email, phone, order details |
| Manage your account & authentication | Email, hashed password, Google ID |
| Send order confirmations & shipping updates | Email, order status |
| Handle warranty claims | Name, address, product data, issue photos |
| Provide customer support | Contact details, order history |
| Send promotional emails (with consent) | Email, purchase history |
| Detect fraud and secure the platform | IP address, device data, payment signals |
| Improve the website and product catalogue | Aggregated usage analytics |
| Comply with legal obligations | Identity, transaction records |
4. Legal Basis for Processing
Where the GDPR or equivalent legislation applies, we process your personal data under the following lawful bases:
- ContractProcessing necessary to fulfil your order, manage your account, and deliver purchased products.
- ConsentMarketing emails, analytics cookies, and advertising cookies — only when you have given clear, affirmative consent via our cookie banner or account settings.
- Legitimate InterestFraud prevention, platform security, aggregated analytics to improve our services — where our interests do not override your rights.
- Legal ObligationRetaining transaction records for tax purposes and complying with court orders or regulatory requests.
5. Data Sharing & Disclosure
We do not sell your personal data to third parties. We share data only in the following circumstances:
- Delivery & logistics partners: your name, address, and phone number are shared with couriers to fulfil shipments.
- Payment processors (PayHere, Stripe): your payment details are handled directly by these PCI-DSS certified processors — we receive only transaction references.
- Cloud infrastructure (AWS S3, database hosting): your data is stored on secure cloud servers under appropriate data processing agreements.
- Google LLC: if you use Google sign-in, your token is verified with Google's OAuth API.
- Legal requirements: we may disclose data if required by law, court order, or to protect the rights and safety of Emore, our customers, or the public.
- Business transfers: in the event of a merger, acquisition, or asset sale, your data may be transferred — you will be notified via email before this occurs.
6. Data Retention
| Data Category | Retention Period |
|---|---|
| Active account data | While your account is active |
| Order & transaction records | 7 years (legal/tax requirement) |
| Warranty claims | 2 years after claim closure |
| Product reviews & Q&A | Until account deletion or content removal request |
| Marketing consent records | 3 years from last consent action |
| Server access logs | 90 days |
| Cookie consent records | Stored as long as account is active |
When data is no longer needed, it is securely deleted or anonymised.
7. Your Rights
Depending on your jurisdiction you have some or all of the following rights:
Right to Access
Request a copy of the personal data we hold about you.
Right to Rectification
Correct inaccurate or incomplete data in your account.
Right to Erasure
Request deletion of your personal data (“right to be forgotten”), subject to legal retention obligations.
Right to Portability
Receive your data in a structured, machine-readable format (JSON / CSV).
Right to Restrict Processing
Ask us to pause processing while you contest accuracy or await a complaint outcome.
Right to Object
Object to processing based on legitimate interest, including direct marketing.
Right to Withdraw Consent
Withdraw any consent at any time without affecting prior lawful processing.
Right to Lodge a Complaint
File a complaint with your national data protection authority.
To exercise any right, email [email protected] or write to us at the address below. We will respond within 30 days. You may also manage certain preferences directly in your account settings.
9. Security
We implement industry-standard technical and organisational security measures to protect your personal data:
- All data is transmitted over encrypted connections (HTTPS everywhere).
- Passwords are protected with industry-standard adaptive hashing — we never store plaintext passwords.
- Authentication uses short-lived access tokens with automatic, rotating session renewal.
- CSRF protection on all state-mutating API endpoints.
- Database and server access is restricted to authorised personnel only.
- Container images are scanned for known vulnerabilities before deployment.
Despite these measures, no method of transmission over the internet or electronic storage is 100% secure. If you discover a security vulnerability, please disclose it responsibly to [email protected].
10. Children's Privacy
Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately at [email protected] and we will delete it promptly.
11. International Data Transfers
Some of our service providers (e.g., AWS, Google) operate outside Sri Lanka. When we transfer data internationally, we ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Transfers only to countries with an adequacy decision, or to providers certified under equivalent frameworks.
- Data Processing Agreements with all sub-processors.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on our website at least 14 days before taking effect. The “Last updated” date at the top of this page reflects the most recent revision. Continued use of our services after the effective date constitutes acceptance of the updated policy.
13. Contact Us
For any privacy-related questions, data subject requests, or complaints: